Skip to content
Last updated

mcp

Products:RedocRedocRevelRevelReefReefRealmRealm
Plans:EnterpriseEnterprise+

Redocly automatically generates Model Context Protocol (MCP) servers from your documentation and OpenAPI descriptions. MCP servers make your content accessible to AI tools in the MCP ecosystem (such as ChatGPT, Claude, Cursor, Goose).

Options

OptionTypeDescription
hidebooleanHide the MCP server globally. When set to true, all MCP functionality is disabled. Default: false.
docsDocs objectDocs MCP configuration options.

Docs object

OptionTypeDescription
hidebooleanHide the Docs MCP server. Default: false.
namestringSet the name displayed to MCP clients during the initial connection. Default: "Docs MCP server".
ignore[string]List of glob patterns, matched against file paths, for content to exclude from the MCP server. Default: [].
publicEndpointbooleanServe an additional MCP endpoint at /mcp-public that requires no authentication. The endpoint ignores any provided credentials and exposes only content available to the anonymous team. It never grants access to protected content. Useful when RBAC restricts some content but public content must stay reachable for AI tools without a login. Before you enable it, review which content your RBAC rules grant to the anonymous team: that content becomes reachable without a login. When the project has no protected content, /mcp already serves anonymous users and the /mcp-public endpoint is not registered. The rbac.features.mcp configuration also applies to this endpoint: it must grant access to the anonymous team, or the /mcp-public endpoint is not registered. With requiresLogin and no rbac rules, no content is public, so the /mcp-public endpoint is not registered. Default: false.

Access control

Role-based access control (RBAC) that protects content in your project also protects that content over the Docs MCP server. The Docs MCP server enforces access with the same RBAC engine as the portal. Each authenticated client receives only the API descriptions, schemas, skills, and search results that its teams are permitted to access. That is the same content the client could see in the portal.

When RBAC restricts anonymous access, the /mcp endpoint requires authentication and returns 401 to unauthenticated clients. To restrict the server itself rather than individual content, set a team-based role for the mcp feature. The steps are described in Restrict access to the MCP server.

The hide and ignore options remove content from the build for all clients. They are build-time removal, not access control — use RBAC to control who can access content.

Examples

Basic configuration

# Global settings
mcp:
  hide: false
  # Docs MCP settings
  docs:
    hide: false
    name: My Custom Docs MCP Server

Public endpoint for anonymous users

Serve public content to unauthenticated MCP clients on a project with restricted content:

mcp:
  docs:
    publicEndpoint: true

Everything your RBAC rules grant to the anonymous team becomes reachable over /mcp-public without a login. Review these rules before you enable the endpoint.

Authenticated users keep connecting to /mcp. Anonymous users and unauthenticated integrations connect to /mcp-public and receive only the content that is available to the anonymous team. A browser visit to /mcp-public displays the setup page with connection snippets for the public endpoint. The two setup pages link to each other. The 401 response from the restricted /mcp endpoint mentions the public URL.

Ignore specific patterns

Ignore files and file path patterns in the MCP server:

# Global settings
mcp:
  hide: false
  docs:
    hide: false
    # Ignored patterns
    ignore:
      - openapi-files/**
      - '**/test-endpoints*'

Default configuration

mcp:
  hide: false
  docs:
    hide: false
    name: Docs MCP server
    publicEndpoint: false

Resources